LG Electronics USA to Suspend Smart TV Apps Enabling Residential Proxy Nodes

The home appliance giant LG Electronics USA announced this week its intention to suspend any applications built for its smart TVs that transform user televisions into always-on residential proxy nodes. This decisive action follows closely on the heels of research revealing a significant security and privacy vulnerability: over 42 percent of applications available on LG’s webOS store permit unknown third parties to route their internet traffic through a user’s television. The move underscores a growing concern within the tech industry regarding the potential misuse of connected devices and the opaque practices of some app developers.
The Shadow of Residential Proxies in Smart TVs
The revelation emerged less than a month after a comprehensive study by the cybersecurity firm Spur brought the issue to light. Spur’s research, detailed in a July 2nd report, meticulously examined the prevalence of residential proxy software development kits (SDKs) embedded within smart TV applications. Their findings were stark: on LG’s smart TVs operating on the webOS platform, a staggering 42 percent of downloadable apps incorporated SDKs that effectively turned the user’s television into a persistent proxy node. This means that the internet traffic of individuals or entities paying for proxy services could be routed through unsuspecting LG TV owners’ internet connections.
The implications of such a setup are far-reaching. A residential proxy allows users to route their internet traffic through another user’s IP address, effectively masking their own online activity. While legitimate uses exist, such as market research or content access for geographically restricted material, the practice is also exploited for illicit activities, including the circumvention of security measures, the execution of distributed denial-of-service (DDoS) attacks, and potentially, access to sensitive information on local networks.
Samsung’s Tizen operating system, another major player in the smart TV market, was not spared from Spur’s scrutiny. The research indicated that more than a quarter of apps designed for Samsung’s Tizen OS also contained similar residential proxy components, suggesting a broader trend across the smart TV ecosystem.
LG’s Response: A Swift and Decisive Stance
In response to KrebsOnSecurity’s inquiries regarding Spur’s findings, John Taylor, Senior Vice President at LG Electronics, communicated the company’s commitment to addressing the issue. Taylor stated that LG is actively engaging with app developers to ensure the removal of residential proxy functionalities from their applications on the webOS platform. He issued a clear ultimatum: developers who fail to comply with this directive will face the suspension of their apps.
"A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform," Taylor explained. "If this option is not removed, these apps will be suspended."
This statement signifies a significant shift in LG’s approach to app vetting and platform integrity. Taylor further emphasized LG’s dedication to preventing residential proxy networks from being integrated into its smart TV applications moving forward. The company has initiated a thorough review of existing applications, a process he confirmed is "well underway now."
"As part of our ongoing efforts to enhance platform quality and the user experience, LG will continue to strengthen our evaluation process for developer-submitted apps, including those that incorporate residential proxy SDKs," Taylor added in his emailed statement. This suggests a proactive measure to prevent similar issues from arising in the future, indicating a more stringent vetting process for applications seeking to join the webOS app store.
The Monetization of User Bandwidth
The underlying business model driving the inclusion of residential proxy SDKs in smart TV apps involves a lucrative arrangement for developers. App makers can partner with residential proxy providers, integrating specific SDKs into their applications. In return for allowing their application’s users to unknowingly rent out their internet connection as a proxy node, developers receive financial compensation. This revenue stream can be particularly attractive for developers of seemingly simple applications, such as games, screensavers, or utility tools.
Spur’s investigation uncovered that these residential proxy SDKs were bundled with a wide array of applications, ranging from classic games like Pac-Man to basic file management utilities and even screensavers. This broad integration across diverse app categories highlights the pervasive nature of the practice and its appeal to developers seeking alternative monetization strategies beyond traditional advertising or in-app purchases.
One particularly illustrative example identified by Spur involved a Pac-Man smart TV app. This application presented users with a choice: either view advertisements within the game or consent to allow their television to function as a residential proxy node. This "consent" mechanism, often presented in a non-intrusive manner, raises significant questions about the true nature of user agreement and informed consent.

Bright Data’s Defense and Industry Countermeasures
The research by Spur pointed to Bright Data as the dominant provider of residential proxy SDKs across both LG and Samsung smart TV platforms. In a statement provided to KrebsOnSecurity, Bright Data defended its practices, asserting that its network operates on principles of consent and responsibility, and adheres to the terms set by LG and Samsung.
"Every peer opts in through a dedicated screen and receives value in return; every customer is vetted, and our practices have now undergone a second independent audit by PwC," the statement read. "We remain committed to an open, transparent internet where legitimate businesses, researchers, and institutions can responsibly access data that lives in the public domain."
Bright Data and other proxy providers mentioned in Spur’s report maintain that they implement rigorous "know-your-customer" (KYC) processes to verify the legitimacy of their service users. These users are often engaged in activities such as content scraping, which involves collecting data from public websites. The proxy companies also claim to employ technological safeguards designed to prevent their customers from accessing or controlling other devices within the proxy user’s local network. This is a critical assertion, as uncontrolled access to a user’s local network could lead to significant security breaches.
The Amplified Risk and the Call for Transparency
Despite the assurances from proxy providers, cybersecurity experts like Trevor Sutter of Spur argue that the fundamental issue lies not with the existence of residential proxy networks themselves, but with their widespread integration into devices that consumers do not typically perceive as full-fledged computers. Unlike traditional computers, smart TVs are often not subject to the same level of user scrutiny or security auditing.
"A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight," Sutter articulated in his analysis. He further highlighted a critical concern: the amplified risk when consent is obtained from individuals within a household who may not fully comprehend the implications or possess the authority to grant such permission, such as minors. This raises ethical questions about who is truly consenting and whether that consent is fully informed.
A Broader Pattern of Questionable Partnerships
LG’s proactive stance on the residential proxy issue, while commendable, comes at a time when the company is facing scrutiny for other controversial partnerships. Earlier this week, the YouTube channel Gamers Nexus exposed that certain LG high-end LCD monitors were automatically installing software drivers that promoted paid McAfee antivirus subscriptions. This installation occurred via Windows Update without requiring explicit user approval, raising concerns about the transparency and unsolicited nature of the software distribution.
The Gamers Nexus report demonstrated how these LG monitors would install an application that actively pushed for paid McAfee antivirus subscriptions. The method of delivery, through Windows Update without a clear opt-in prompt, has drawn criticism for potentially misleading users or bundling unwanted software. This incident, coupled with the residential proxy issue, paints a picture of a company grappling with the complexities of integrating third-party services and software into its diverse product lines, and the subsequent impact on user trust and security.
Timeline of Events
- July 2nd, 2026: Cybersecurity firm Spur releases research detailing the prevalence of residential proxy SDKs in smart TV applications, highlighting significant concerns for LG and Samsung devices. The report indicates over 42% of LG apps and over 25% of Samsung apps contain these SDKs.
- July 2026 (following Spur’s report): LG Electronics USA is contacted for comment regarding Spur’s findings.
- This Week (July 2026): LG Electronics USA publicly announces its plan to suspend smart TV apps that enable residential proxy nodes, following the investigation by KrebsOnSecurity into Spur’s research. John Taylor, LG Senior Vice President, confirms the company’s stance and enforcement plans.
- Concurrent to LG’s announcement: Reports emerge regarding LG monitors automatically installing McAfee promotion software via Windows Update without explicit user consent, as highlighted by Gamers Nexus.
- July 22nd, 2026, 1:06 p.m. ET: An update is added to the original reporting, including a statement from Bright Data addressing the accusations.
Broader Implications and Future Outlook
The actions taken by LG Electronics USA represent a significant step towards safeguarding user privacy and security on smart TV platforms. The widespread integration of residential proxy SDKs, often with opaque consent mechanisms, had created a hidden vulnerability for millions of users. By committing to suspending non-compliant applications, LG is sending a clear message to app developers about the expected standards of transparency and responsible data handling.
However, the broader implications extend beyond LG’s webOS platform. The research from Spur suggests that this is a systemic issue within the smart TV app ecosystem. Samsung’s Tizen OS, and potentially other smart TV operating systems, may harbor similar vulnerabilities. The onus now falls on other manufacturers to conduct similar audits of their app stores and take decisive action to protect their user bases.
Furthermore, the incident highlights the critical need for enhanced regulatory oversight and industry-wide best practices concerning the integration of SDKs and third-party software in connected devices. Consumers are increasingly relying on smart TVs for entertainment and information, and the potential for these devices to be inadvertently co-opted for surreptitious data routing or malicious activities poses a significant threat to online safety.
The commitment by proxy providers like Bright Data to vetting customers and implementing technical safeguards is a positive signal, but as Spur’s analysis suggests, these measures may not be sufficient to address the inherent risks of embedding such functionalities in consumer electronics. The concept of "informed consent" in the context of smart TV apps requires re-evaluation, moving beyond simple prompts to more robust and ongoing mechanisms for user control and awareness.
LG’s dual recent controversies – the residential proxy issue and the McAfee promotion software – underscore the complex challenges faced by large electronics manufacturers in managing their vast product ecosystems and partnerships. As consumers continue to integrate smart devices into their daily lives, the demand for greater transparency, robust security, and ethical data practices will only intensify. The actions of LG and the scrutiny from researchers and media outlets are crucial in driving this necessary evolution within the connected device industry.





